Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'wininit' = '%ALLUSERSPROFILE%\Application Data\wininit\svchost.exe'
- '%ALLUSERSPROFILE%\Application Data\wininit\svchost.exe'
- '<SYSTEM32>\cmd.exe' [zoneTransfer]ZoneID = 2 > "%ALLUSERSPROFILE%\Application Data\wininit\svchost.exe":ZONE.identifier
- %ALLUSERSPROFILE%\Application Data\wininit\svchost.exe
- %ALLUSERSPROFILE%\Application Data\wininit\svchost.exe